Ecommerce Security: How to Protect Your Store, Customers and Payments
Ecommerce security in layers: staff accounts, customer accounts, payments and scripts, platform and apps, data protection, monitoring, incident response and testing.
Quick answer
Secure an online store in layers. Protect accounts with multi-factor authentication and least-privilege access for staff, and bot and takeover protection for customers. Keep card data off your systems with hosted checkout or tokenization, and control scripts on payment pages. Maintain the platform: patch, review apps and their permissions, manage secrets and set security headers. Back up, monitor, prepare an incident response plan and get professional security testing for custom code. This article is general guidance, not a security assessment.
The Ecommerce Threat Picture
Online stores hold what attackers want: payment flows, customer personal data, accounts with stored value (loyalty points, gift cards) and inventory that can be resold. Common incidents include compromised staff or admin accounts, customer account takeover through reused passwords, malicious scripts injected into checkout or product pages, vulnerable or over-permissioned apps and plugins, misconfigured storage exposing data, and fraud such as card testing.
This article explains defensive controls at a strategic level. It doesn't describe attack techniques, and it isn't a substitute for professional testing. For general website security, see website security checklist and secure website development.
| Risk | Typical impact | Primary defences |
|---|---|---|
| Staff account compromise | Full store control, data access | MFA, least privilege, access reviews |
| Customer account takeover | Fraud, loyalty theft, data exposure | Bot protection, rate limits, MFA options, breach detection |
| Malicious scripts on payment pages | Card and personal data theft | Hosted payment pages, script inventory, integrity monitoring |
| Vulnerable or excessive apps and plugins | Data access, site compromise | App review, minimal scopes, updates |
| Misconfiguration | Data exposure | Secure defaults, configuration reviews |
| Card testing and payment fraud | Chargebacks, fees | Fraud tools, velocity limits, bot protection |
Layer 1: Staff and Admin Accounts
Most store compromises start with an account. Enforce multi-factor authentication for every staff account on the ecommerce platform and on connected systems: email, domain registrar, DNS, hosting, code repositories, payment provider and analytics. Give each person their own account with only the permissions they need, remove access promptly when people leave or agencies finish work, and review access regularly. Broken access control has ranked first in the OWASP Top 10 web application risks (OWASP Top 10), and many real incidents come from over-privileged or forgotten accounts.
- MFA on platform, email, domain, DNS, hosting, repositories, payments
- Individual accounts, no shared logins
- Role-based permissions; admin rights limited
- Collaborator and agency access time-limited and reviewed
- Quarterly access review with owners
- Offboarding checklist that removes all access
Layer 2: Customer Accounts
Customer accounts are targeted with credentials leaked from other sites. Defences include bot protection and rate limiting on login and account creation, detection of unusual login patterns, optional or risk-based MFA or passwordless login, notification of account changes (email, address, password) and protection of stored value such as loyalty points and gift card balances. Balance security with accessibility: avoid puzzle CAPTCHAs that block disabled users, and allow password managers. See ecommerce accessibility.
Layer 3: Payments and Scripts
The safest approach is to keep card data off your systems entirely: use a hosted checkout or payment fields provided by your payment provider, and tokenization for stored payment methods. This reduces your PCI DSS scope but doesn't remove responsibility. PCI DSS v4.0.1 is the current version, and requirements that became mandatory on 31 March 2025 include managing scripts on payment pages and detecting unauthorized changes. The PCI Security Standards Council has clarified how these apply to merchants using embedded payment pages under SAQ A (PCI Security Standards Council). Confirm your obligations with your payment provider or a qualified assessor.
Beyond compliance, control scripts across the store: keep an inventory of third-party scripts, remove unused ones, load them only where needed, use a content security policy where practical, and monitor for unexpected changes.
Unsure how exposed your store is?
ZSpace reviews ecommerce setups, apps, scripts and integrations and helps prepare for professional security testing.
Layer 4: Platform, Apps and Code
On hosted platforms, focus on what you control: apps, themes, integrations and settings. Install only necessary apps from reputable developers, review the data access they request, and remove unused ones. On self-hosted or custom platforms, patch the platform, plugins and dependencies promptly, run dependency scanning, and follow secure development practices. Keep secrets (API keys, tokens) out of code and front-end bundles, store them in a secrets manager or environment configuration, rotate them, and give each integration its own limited credentials.
| Area | Hosted platform (e.g. Shopify) | Self-hosted / custom |
|---|---|---|
| Infrastructure and patching | Platform | You |
| Checkout security | Platform (hosted checkout) | You or payment provider |
| Apps and plugins | You choose and review | You choose, patch and review |
| Theme / frontend code | You | You |
| Integrations and APIs | You | You |
| Staff access | You | You |
Layer 5: Data Protection
Collect only the customer data you need, restrict access to it, encrypt it in transit (HTTPS everywhere) and at rest where you control storage, and set retention periods. Be careful with exports: order and customer exports in spreadsheets, shared drives or email are a common source of leaks. Security and privacy overlap here. See ecommerce privacy and customer data.
Layer 6: Fraud and Bots
Fraud tools provided by payment providers and platforms score orders for risk. Configure them, review flagged orders and use velocity limits to reduce card testing. Bot management helps with credential stuffing, scraping, inventory hoarding during launches and fake account creation. Monitor chargeback rates, which card networks and payment providers track.
Layer 7: Monitoring, Backups and Incident Response
Monitor for signs of trouble: unexpected admin logins, new apps or staff accounts, changes to themes or scripts, spikes in failed logins or declined payments, and unusual data exports. Keep backups of data and code you control and test restoring them. Write an incident response plan covering roles, contacts (platform support, payment provider, legal advisers), containment, evidence preservation, notification (duties vary by jurisdiction) and recovery. Practise it.
- Alerts for new admins, apps and theme changes
- Login and payment anomaly monitoring
- Tested backups for data and code you control
- Incident response plan with named roles and contacts
- Legal advice identified for breach notification
- Post-incident review process
Security for AI Features
AI assistants, agents and integrations add new risks: prompt injection, over-permissioned tools, leakage of customer data to model providers and actions taken on manipulated inputs. Apply the same principles: least privilege, validation, logging, human approval for high-impact actions and data minimization. See AI agents for ecommerce.
Professional Testing
Guidance and checklists help you get basics right; they don't find everything. Custom code, headless storefronts, integrations and larger stores warrant professional security testing by qualified specialists, with appropriate authorization and scope. Use an internal review to prepare for that testing and to fix obvious gaps first. See ecommerce security audit.
Security for Headless and Custom Builds
Headless storefronts and custom integrations move more responsibility to your team. API tokens must be scoped correctly (public storefront tokens vs private server tokens), secrets must stay server-side, server routes need input validation and rate limiting, and hosting needs secure configuration. Dependencies must be kept up to date. These builds warrant professional security testing before launch and after major changes. See Hydrogen vs traditional Shopify.
- Public and private API tokens used in the right places
- No secrets in client bundles or public repositories
- Input validation and rate limiting on server routes
- Dependency updates and scanning
- Secure hosting configuration and headers
- Professional testing before launch
Security Responsibilities Across Teams
Security fails when everyone assumes someone else owns it. Assign clear responsibilities: platform and access to an operations or ecommerce lead, code and integrations to engineering, scripts and tags to marketing with engineering review, vendor review to whoever approves apps, and incident response to a named lead with backup. Review responsibilities when teams or agencies change.
| Area | Typical owner |
|---|---|
| Staff accounts and permissions | Ecommerce or operations lead |
| Apps and vendors | Ecommerce lead with engineering review |
| Theme and custom code | Engineering or agency |
| Tags and scripts | Marketing with engineering approval |
| Payments and fraud | Finance or operations |
| Incident response | Named lead and deputy |
Training Staff
Many compromises start with phishing or social engineering aimed at staff: fake platform notices, requests to add a collaborator, changes to payout details. Train staff to verify unusual requests through a separate channel, report suspicious messages, and never share MFA codes. Keep training short and repeated, and include agencies and contractors with admin access.
Common Mistakes
- No MFA on email, domain or payment accounts
- Shared admin logins
- Old agency and app access never removed
- Unreviewed third-party scripts on checkout-adjacent pages
- Secrets in front-end code or repositories
- Customer exports left in shared folders
- Assuming the platform handles everything
Ready to strengthen your store's security?
Talk to ZSpace about secure ecommerce development, Shopify app and access reviews and security monitoring automation.
Conclusion
Ecommerce security is layered: protect accounts, keep card data off your systems and control scripts, maintain apps and code, minimize data, fight fraud and bots, monitor and prepare for incidents, and use professional testing for what checklists can't cover. Related: ecommerce compliance and mobile app security.
Common questions
Compromised staff accounts, account takeover of customer accounts, malicious or vulnerable third-party scripts and apps (including payment page skimming), misconfiguration, unpatched software, exposed secrets, fraud and bots, and data leaks.